nordea.se
HTML metadata
Technology
- Server
- nginx
- CMS
- Gatsby
Third-party hosts loaded (1)
- tags.tiqcdn.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns0.nordea.com
- ns1.nordea.com
- ns2.nordea.com
- spdns3.cscdns.net
- MX
-
- 10 nordea-se.mail.protection.outlook.com
- TXT
-
Show 8 TXT records
mandrill_verify.-P0fY02mFFIb__YuHK0-Vgrfy0qqbjx09n8dcyjr4zm033dhfmkfzdzhpf1tdjhd7kxzw3jbphckc5zjnd98c588ebf28e-1a96-4f25-9bba-fb32a90688a1jzdv1n6bxf9b3hz9rnjxlhq8dlhp9g4xS8XGJnzrs07woA9tstdqUWdme4BYVygD6jfdteKYdnFW3YLo5CBC7WSiQxWAZ0gMB5+1tHgT0iiwCK5kFCUtMg==F4WTFX6OnEurUA7jTfcVMD+UYxBt3mhBvaGvdRJGdJdPqRArj32DOPuWysqb0ylY9OmzFEEUJg+/B+NDWGQvEA==fnyj6rtg9c7wg0c2bdh8n4v1qyy0s9cp
- Verified for
-
- Adobe
- Apple
- Meta
- Microsoft 365
Email authentication strong
- SPF
-
v=spf1 include:spf.messagelabs.com ip4:91.196.240.18 ip4:91.196.240.17 include:_spf.anpdm.com ip4:193.234.184.22/31 include:sendgrid.net ip4:192.254.122.173 ip4:167.89.22.98 include:spf.protection.outlook.com include:spf.mandrillapp.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:nordea@rua.agari.com; ruf=mailto:nordea@ruf.agari.compolicy: reject (enforced) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCkude+7egSlyK819cabqJXeM5XeNyT2RgMYC+G3ltbdatHF6MSfgQ1KEs12usr5DCK8V2ZlhXI48jVET4Tpe… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxSyw11KUFQ9lv+3Nob2XXCbGXUv0ffi5fC+qLGrL0fRAFCD5vN4EjIVpWQ3OMCNo2PoqUHRv+GCZIZ3YCx… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCunzWhCPJ4qqnSOsqSd4EI9CZICihFXuZnX9Mht9evTO1TZRc44JFO570JsA5rWRMKrMNEpdWS/ue6iIV0Mvxftm…
selectors probed - selector1:
Certificate (current)
DigiCert G2 TLS EU RSA4096 SHA384 2022 CA1
Expires in 154 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'nonce-6d84c9b6-8959-4ed9-acad-bdc46b4d183e' 'strict-dynamic' https: 'unsafe-inline' 'unsafe-eval';connect-src 'nonce-6d84c9b6-8959-4ed9-acad-bdc46b4d183e' https: 'unsafe-inline';style-src * 'unsafe-inline'; img-src * data:; font-src * data:;frame-src *.demdex.net *.skat.dk;- strict-transport-security
max-age=157680000